Protected Pre-Association Station Identification for Consistent WLAN Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing use of randomized MAC addresses in wireless devices poses challenges for WLAN infrastructure, leading to a perceived loss of utility as users are forced to log in frequently due to unrecognized stations, and existing systems fail to balance privacy with the ability to track and provide features like parental controls.
Innovation Solution
An access point requests a unique identifier from a station before association, establishes a secure connection, and receives a unique identifier response, which can be different from the MAC address, allowing for personalized features and policies based on the response.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Object-affected harmful factors
If randomized MAC addresses are used for privacy protection, then user privacy is improved, but the ability to consistently identify stations across associations deteriorates
Solution Approach 1:
The patent segments the identification system into two parts: randomized MAC addresses for general communication and protected pre-associated station identifiers for consistent identification. This allows the system to use different identifiers for different purposes, maintaining both privacy and reliable identification.
Solution Approach 2:
The patent introduces protected pre-associated station identifiers as an intermediary mechanism between the station and access point. These identifiers are exchanged through a protected pre-association mechanism, serving as a mediator that enables consistent identification without exposing the randomized MAC addresses.
2Object-affected harmful factors
If randomized MAC addresses are used, then privacy is improved, but user convenience deteriorates due to frequent re-login requirements
Solution Approach 1:
The patent implements preliminary action by establishing protected pre-association between stations and access points before actual network connection. During this pre-association phase, identifiers are exchanged and stored, enabling automatic recognition and eliminating the need for frequent re-logins when the station reconnects.
3Measurement precision
If unique identifiers are exchanged after association, then identification accuracy is improved, but security deteriorates due to potential interception
Solution Approach 1:
The patent performs the identifier exchange action preliminarily, before the formal association process. By establishing the protected pre-association channel first, the identifiers are exchanged in a secure environment before any potential security risks of post-association exchange arise.
Solution Approach 2:
The patent uses a protected pre-association mechanism as an intermediary channel for identifier exchange. This intermediary channel provides security protections that prevent interception and unauthorized access, ensuring secure transmission of unique identifiers.
Data Source
Figure 1
Figure 2A~2B
Figure 3A~3B
AI summary
Methods, systems, and computer readable media can be operable to facilitate an exchange of messages between an access point and a station, wherein the access point requests a unique identifier from the station. The station initiates a secure connection with the access point prior to associating with the access point. The station may either respond with a message declining to provide a unique identifier or respond with a message including a unique identifier to be used by the access point for the station via the secure connection. The response from the station may include additional limitations on the use of the unique identifier by the access point. The access point may enforce different policies against the station depending upon how the station responds to the unique identifier request.